← Back

Mac Os X

mac_os_x

Vendor: Apple • 3,210 CVEs

CVEs (3,210)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Sep 16, 2008
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Network Preferences in Apple Mac OS X 10.4.11 stores PPP passwords in cleartext in a world-readable file, which allows local users to obtain sensitive information by reading this file.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Sep 16, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrary code via a document containing a crafted font, related to "PostScript...Show more
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrary code via a document containing a crafted font, related to "PostScript font names."Show less
4Apple
CanonicalDebian+1 more
6Debian Linux
Iphone OsLibxml2+3 more
Apr 23, 2026
Sep 12, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML enti...Show more
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.Show less
4Apache
AppleCanonical+1 more
4Http Server
Mac Os XOpensuse+1 more
Apr 23, 2026
Aug 6, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote at...Show more
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Aug 4, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Repair Permissions tool in Disk Utility in Apple Mac OS X 10.4.11 adds the setuid bit to the emacs executable file, which allows local users to gain privileges by executing commands within emacs.
1Apple
1Mac Os X
Apr 23, 2026
Aug 1, 2008
N/A· v4
8.1 HIGH· v3
7.5 HIGH· v2
Apple Mac OS X does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
2Apple
Canonical
2Mac Os X
Ubuntu Linux
Apr 23, 2026
Jul 18, 2008
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized point...Show more
Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jul 1, 2008
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically proximate attackers to gain access to a locked session in (1) sleep mode or (2) screen saver mode via unspecified vectors.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jul 1, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local users to gain privileges by inserting a Trojan horse file into this directory.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jul 1, 2008
N/A· v4
N/A· v3
7.6 HIGH· v2
Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a do...Show more
Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a downloaded file.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jul 1, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2)...Show more
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jul 1, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsa...Show more
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jul 1, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms allows local users to gain privileges or cause a denial of service (memory corruption and application crash) by resolving...Show more
Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms allows local users to gain privileges or cause a denial of service (memory corruption and application crash) by resolving an alias that contains crafted AFP volume mount information.Show less
1Apple
1Mac Os X
Apr 23, 2026
Jun 23, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of scripting addition plugins, which allows local users to gain privileges v...Show more
Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of scripting addition plugins, which allows local users to gain privileges via scripting addition commands to a privileged application, as originally demonstrated by an osascript tell command to ARDAgent.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jun 2, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message produced upon access to a nonexistent blog.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jun 2, 2008
N/A· v4
N/A· v3
2.1 LOW· v2
The sso_util program in Single Sign-On in Apple Mac OS X before 10.5.3 places passwords on the command line, which allows local users to obtain sensitive information by listing the process.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jun 2, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Unspecified vulnerability in the Pixlet codec in Apple Pixlet Video in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie f...Show more
Unspecified vulnerability in the Pixlet codec in Apple Pixlet Video in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file, related to "multiple memory corruption issues."Show less
1Apple
1Mac Os X
Apr 23, 2026
Jun 2, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Mail in Apple Mac OS X before 10.5, when an IPv6 SMTP server is used, does not properly initialize memory, which might allow remote attackers to execute arbitrary code or cause a denial of service (application crash), or...Show more
Mail in Apple Mac OS X before 10.5, when an IPv6 SMTP server is used, does not properly initialize memory, which might allow remote attackers to execute arbitrary code or cause a denial of service (application crash), or obtain sensitive information (memory contents) in opportunistic circumstances, by sending an e-mail message.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jun 2, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Unspecified vulnerability in the Apple Type Services (ATS) server in Apple Mac OS X 10.5 before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via a crafted embedded font in a PDF document, relate...Show more
Unspecified vulnerability in the Apple Type Services (ATS) server in Apple Mac OS X 10.5 before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via a crafted embedded font in a PDF document, related to memory corruption that occurs during printing.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jun 2, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Integer overflow in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image that triggers a heap-based buffe...Show more
Integer overflow in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image that triggers a heap-based buffer overflow.Show less